T09 · Insecure Skill Coding Practices
- Location
references/security-checklist.md:49- Finding
Kraken API Credentials Are Embedded Directly in Docker Compose Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a mostly coherent Freqtrade setup guide, but it handles real trading credentials and tells users to run mutable upstream Docker code with some unclear credential-storage guidance.
Review before installing. Use only a pinned, reviewed Freqtrade release or image digest, keep Kraken withdrawal permission disabled, start in dry-run mode, and store real API keys only in a gitignored secret file or a secrets manager, not directly in docker-compose.yml or config files.
references/security-checklist.md:49Kraken API Credentials Are Embedded Directly in Docker Compose Configuration
SKILL.md:34Mutable Remote Freqtrade Repository Is Retrieved and Executed Without Version Pinning
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Add to .gitignore immediately:
echo ".env" >> .gitignore
In user_data/config.json, leave the exchange key and secret as empty strings — Freqtrade will populate them from the env vars automatically:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Good ✅
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Good ✅
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Good ✅
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Good ✅
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Good ✅
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
rm .env # Delete the old one
### Running Freqtrade Safely
No suspicious patterns detected.